Updated on
Website visits
The official website, rivloom.com, provides product information, guides, download status, and updates. It currently has no account registration, payment, or online feedback submission forms. See the download page for available installers.
The website is served through Cloudflare Pages and its global network. Cloudflare processes access requests to deliver content and protect the service; this may involve IP addresses, traffic routing, browser information, and operating system information. For processing and retention arrangements, see the Cloudflare Privacy Policy.
When an installer is available, it is delivered through downloads.rivloom.com. Cloudflare storage and network services process file download requests. Downloads do not require a website account and do not upload your desktop tasks or model credentials to the website.
The website uses Cloudflare Web Analytics (real user monitoring, or RUM) to understand visits and improve the page experience. Metrics include visits and page views, page addresses and referrers, country or region, browser, device type, operating system, and performance measures such as page loading, layout stability, and interaction responsiveness. Cloudflare receives and processes the data; we view the website statistics. See the Web Analytics dimensions.
Statistics are currently limited by Cloudflare's setting to exclude data from visitors in the European Union. According to Cloudflare's RUM data and privacy documentation, the analytics script does not read or write browser storage such as cookies or localStorage. The RUM service receives the source IP with an HTTP request and discards it at the nearest data center, without storing it in the core RUM database or logs. RUM data may be processed outside the visitor's country or region.
These RUM rules differ from those for CDN and security services, which may use necessary cookies depending on enabled features. See the Cloudflare cookie documentation.
This website analytics service does not read task content, work files, model credentials, or conversations from the Rivloom desktop client. Desktop data use is described below.
Desktop files and model requests
Work files stay on the execution device. When using AI, prompts, relevant project content, and tool results may be sent to your chosen model provider. Rivloom is not offline AI. Check the model service's data policy before working with confidential information.
Information exchanged by paired devices
After pairing, devices exchange information needed for collaboration over authenticated, encrypted connections. This includes device and project names, execution capabilities, and content and status related to your tasks. Local notes are not sent to the other device, and complete queues from other sources are not broadcast to every device.
Task text and tool output may still contain sensitive information. Field limits and content processing cannot guarantee detection of every secret or path. Do not include keys or production secrets in tasks.
Local records and model credentials
Task records are stored in the device's data directory, and not all content is encrypted. Do not upload that directory publicly. Model credentials are managed by the execution device. Tasks from trusted devices may consume the same account quota; separate billing per member is not guaranteed.
The application does not automatically import your existing personal model credentials. When using an explicit import feature, select only account information you are authorized to use.
Protect your information in feedback
Before sharing screenshots or error descriptions, hide keys, personal information, project paths, and task content that should remain private. Do not send the complete runtime data directory. Private testers can contact their original inviter. See current options under Feedback & support.
If new data collection features are added, this notice will be updated to reflect them. For execution permissions and side effects, see Security boundaries.